US2025371131A1PendingUtilityA1

Preventing Prompt Injection Attacks

Assignee: BANK OF AMERICAPriority: Jun 3, 2024Filed: Jun 3, 2024Published: Dec 4, 2025
Est. expiryJun 3, 2044(~17.8 yrs left)· nominal 20-yr term from priority
G06F 2221/034G06F 21/52
57
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Aspects of the disclosure relate to using machine-learning large language models to prevent prompt injection attacks to protect enterprise-managed information and resources. In some embodiments, a computing platform may receive a prompt injection request which is segmented for analysis. The segmented prompt injection request may be analyzed to determine if new learnings are required. If new learnings are required, knowledge graphs are generated to determine new rules for the machine-learning large language model to prevent deceptive prompt injection attacks. The generated new rules may be analyzed to determine the impact on the enterprise based on key performance metrics or organizational health factors before approval and implementation.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computing platform, comprising: 
 at least one processor;   a communication interface communicatively coupled to the at least one processor; and   memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: 
 receive a prompt injection request; 
 segment the prompt injection request; 
 determine if the prompt injection request is an unknown prompt injection request; 
 if the prompt injection request is determined to be an unknown prompt injection request, determine if learnings are required for execution of the received prompt injection request; 
 if new learnings are required for execution of the prompt injection request, generate knowledge graphs; and 
 determine at least one new rule based on the generated knowledge graphs, the determined new rule for preventing prompt injection attacks associated with prompt injection requests. 
   
     
     
         2 . The computing platform of  claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: 
 score the at least one new rule to determine if the at least one new rule reaches a predetermined threshold for implementing the at least one new rule.   
     
     
         3 . The computing platform of  claim 2 , wherein scoring the at least one new rule comprises scoring the at least new rule based on security factors. 
     
     
         4 . The computing platform of  claim 3 , wherein scoring the at least one new rule comprises scoring the at least one new rule based on sustainability factors. 
     
     
         5 . The computing platform of  claim 4 , wherein scoring the at least one new rule comprises scoring the at least one new rule based on revenue factors. 
     
     
         6 . The computing platform of  claim 5 , wherein scoring the at least one new rule comprises scoring the at least one new rule based on resilience factors. 
     
     
         7 . The computing platform of  claim 2 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: 
 update a knowledge repository associated with the computer platform based on the at least one new rule meeting or exceeding the predetermined threshold for implementing the at least one new rule.   
     
     
         8 . A method, comprising: 
 at a computing platform comprising at least one processor, a communication interface, and memory: 
 receiving a prompt injection request; 
 segmenting the prompt injection request; 
 determining the prompt injection request is an unknown prompt injection request; 
 if the prompt injection request is determined to be an unknown prompt injection request, determining if learnings are required for execution of the received prompt injection request; 
 if new learnings are required for execution of the prompt injection request, generating knowledge graphs; and 
 determining at least one new rule based on the generated knowledge graphs, the determined new rule for preventing prompt injection attacks associated with prompt injection requests. 
   
     
     
         9 . The method of  claim 8 , the computer platform further comprising: 
 scoring the at least one new rule to determine if the at least one new rule reaches a predetermined threshold for implementing the at least one new rule.   
     
     
         10 . The method of  claim 9 , wherein scoring the at least one new rule comprises scoring the at least new rule based on security factors. 
     
     
         11 . The method of  claim 10 , wherein scoring the at least one new rule comprises scoring the at least one new rule based on sustainability factors. 
     
     
         12 . The method of  claim 11 , wherein scoring the at least one new rule comprises scoring the at least one new rule based on revenue factors. 
     
     
         13 . The method of  claim 12 , wherein scoring the at least one new rule comprises scoring the at least one new rule based on resilience factors. 
     
     
         14 . The method of  claim 9 , the computer platform further comprising: 
 updating a knowledge repository associated with the computer platform based on the at least one new rule meeting or exceeding the predetermined threshold for implementing the at least one new rule.   
     
     
         15 . One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, a communication interface, and memory, cause the computing platform to: 
 receive a prompt injection request;   segment the prompt injection request;   determine if the prompt injection request is an unknown prompt injection request;   if the prompt injection request is determined to be an unknown prompt injection request, determine if learnings are required for execution of the received prompt injection request;   if new learnings are required for execution of the prompt injection request, generate knowledge graphs; and   determine at least one new rule based on the generated knowledge graphs, the determined new rule for preventing prompt injection attacks associated with prompt injection requests.   
     
     
         16 . The one or more non-transitory computer-readable media storing instructions of  claim 15 , when executed by a computing platform comprising at least one processor, a communication interface, and memory, cause the computing platform to: 
 score the at least one new rule to determine if the at least one new rule reaches a predetermined threshold for implementing the at least one new rule.   
     
     
         17 . The one or more non-transitory computer-readable media storing instructions of  claim 16 , wherein scoring the at least one new rule comprises scoring the at least new rule based on security factors. 
     
     
         18 . The one or more non-transitory computer-readable media storing instructions of  claim 17 , wherein scoring the at least one new rule comprises scoring the at least one new rule based on sustainability factors. 
     
     
         19 . The one or more non-transitory computer-readable media storing instructions of  claim 18 , wherein scoring the at least one new rule comprises scoring the at least one new rule based on revenue factors. 
     
     
         20 . The one or more non-transitory computer-readable media storing instructions of  claim 19 , wherein scoring the at least one new rule comprises scoring the at least one new rule based on resilience factors.

Join the waitlist — get patent alerts

Track US2025371131A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.